Skip to main content

Share story

Security

Attackers accessed, downloaded code from Grafana Labs' GitHub

Attackers accessed, downloaded code from Grafana Labs' GitHub Image: Primary
A threat actor accessed Grafana Labs GitHub environment and downloaded the companys codebase. The open source observability and data visualization firm announced the incident on Sunday. The breach is significant given the firms widespread use across enterprise engineering and DevOps teams worldwide. Grafana Labs is best known for its open source dashboard and visualization platform. It also offers tools for log aggregation, continuous profiling, distributed tracing, and a hosted option. Much of its software is open source. The company also maintains proprietary portions of its codebase. The company stated that no customer data or personal information was accessed during the incident. It found no evidence of impact to customer systems or operations. The company immediately initiated forensic analysis. It believes it has identified the source of the credential leak. The compromised credentials have been invalidated and additional security measures have been implemented. Attackers have threatened to leak the downloaded codebase unless the company pays a ransom. Grafana Labs has said it will not pay the ransom. The decision aligns with the position that paying does not guarantee data recovery and only incentivizes further illegal activity. The company did not identify the attackers by name. A cyber extortion outfit known as Coinbase Cartel claimed the attack. The group has a history of targeting technology companies and publishing stolen code. Grafana Labs has promised to share additional information about the incident once the investigation is complete. An update traced the compromise back to the TanStack npm supply chain attack.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Help Net Security and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Capital
Infrastructure Capital

Clastix raises €2.9 million for Kubernetes infrastructure software

Italian infrastructure software company Clastix has raised €2.9 million in its first external funding round, led by CDP Venture Capital with participation from Mistral and Vertis SGR. Clastix plans to use the seed capital for prod...

AI Science
AI Science

DeliveryGym study shows gains in simulated courier planning

Researchers introduced DeliveryGym, a three-dimensional environment that trains AI agents to plan across a full courier shift, where one delivery can use time, energy or money needed for later orders. In tests across six models an...

AI Science
AI Science

Preprint reports gains from grounding game-coaching AI in live state

Researchers report that rules tying an AI game coach to current match and session data raised its turn-level factual accuracy to 96.7%, from 61.1% for a prompting baseline and 69.8% for another agent design. Session-level accuracy...